Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 2152Segregate Backup Infrastructure With Separate Administrative Authentication

Keep backup servers, repositories and consoles apart from production, and log into them as an administrator through a different authentication system than production uses.

record_voice_over

Plain language

Backups are the thing you fall back on when production is lost, so they must not fall at the same time production does. This control has two parts. First, the backup infrastructure (the backup servers, the repositories where backup data is stored, and the management consoles used to run the backup system) is kept segregated from the production environment rather than sitting on the same network segments and hosts as the systems it protects. Second, administrative access to that backup infrastructure uses a separate authentication mechanism, so the credentials and identity system that grant production administrator rights do not also grant backup administrator rights. The real-world risk is straightforward. Ransomware operators and intruders who gain a production domain administrator account routinely go looking for the backups first, because deleting or encrypting them removes the organisation's ability to recover without paying. If the backup console trusts the same directory as production and the backup repository is reachable from any production server, one compromised administrator account is enough to destroy both the live data and every copy of it. Segregation limits what an attacker inside production can reach, and separate authentication means the credentials they already hold do not open the backup system.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2026

Control Stack last updated

05 Sept 2026

E8 maturity levels

N/A

Topic

Backup modification and deletion

Official control statement

Backup infrastructure, including backup servers, repositories and management consoles, is segregated from production environments and uses a separate authentication mechanism for administrative access.
policyASD Information Security Manual (ISM)ISM-2152
priority_high

Why it matters

If backup infrastructure shares the production environment and its authentication, a single compromised production administrator account or a piece of ransomware that spreads through production can reach the backup servers, wipe or encrypt the repositories, and disable the backup management console. The organisation then has no clean copy to restore from, turning a recoverable incident into permanent data loss, prolonged outage, and possible extortion. Segregated infrastructure with separate administrative authentication keeps at least one recovery path out of the attacker's hands.

settings

Operational notes

Day to day, this control shows up as friction that must be preserved rather than smoothed away. Backup administrators sign in to the backup console with an account that lives in the backup system's own authentication mechanism (a local identity store, a dedicated directory, or an equivalent) and not with their production domain credentials. Network paths between production and the backup servers and repositories are limited to what the backup jobs themselves need, and changes to firewall rules, VLANs or cloud network configuration that would widen that path go through change control with the backup owner's approval.

Watch for drift. Common ways the control quietly erodes include someone joining the backup server to the production domain for convenience, a new repository being provisioned on a production storage array, a console being exposed on the general management network, or a shared "admin" login being reused for both environments. Include backup infrastructure placement and administrative authentication in periodic configuration checks, and treat any new backup component as needing the same segregation and separate login from the day it is built.

build

Implementation tips

  • The infrastructure team documents every component of the backup infrastructure (backup servers, backup repositories and storage targets, and management consoles) and confirms each one is placed in a network zone or environment that is segregated from production, moving any component currently co-located with production systems.
  • The network team restricts traffic between production and the backup zone to only the ports and directions the backup jobs require, using firewall rules, VLAN separation or cloud security groups, and blocks general administrative protocols from production into the backup zone.
  • The backup platform owner configures administrative access to the backup console, servers and repositories to use a separate authentication mechanism from production, such as the backup product's own local accounts or a dedicated identity store that production administrators cannot reach.
  • The backup administrators create distinct administrative accounts within that separate mechanism for each person who manages backups, and remove any production domain accounts or groups that were previously granted administrative rights on the backup system.
  • The change manager adds a standing check to the change process so that any new backup server, repository or console is built inside the segregated zone and onboarded to the separate authentication mechanism before it goes live.
fact_check

Audit / evidence tips

  • AskAsk for a current inventory of backup infrastructure that lists each backup server, repository and management console with its network location.Look atCheck that every component is placed in a zone or environment distinct from production, and that none is listed alongside production hosts or on production storage.GoodAll backup servers, repositories and consoles sit in a separately identified backup zone, and the inventory is complete and recent.
  • AskAsk for network diagrams and the firewall or security group rules governing traffic between production and the backup zone.Look atLook at what production systems can initiate towards backup servers and repositories, and whether administrative protocols are allowed through.GoodOnly the specific ports the backup jobs need are permitted, and administrative access from production into the backup zone is blocked.
  • AskAsk for the authentication configuration of the backup management console and backup servers.Look atIdentify which identity source the console and servers use for administrative login and whether it is the production directory.GoodAdministrative access is authenticated by a mechanism separate from production, such as the backup product's own account store or a dedicated identity store.
  • AskAsk for the list of accounts and groups holding administrative rights on the backup infrastructure.Look atCompare the list against production administrator accounts and groups to see whether any production credentials also grant backup administration.GoodBackup administrative accounts exist only within the separate mechanism and no production domain accounts or groups carry backup administrative rights.
  • AskAsk to observe a backup administrator logging in to the management console, or for a recent authentication log from the console.Look atConfirm which credentials and identity system are used at login and that a production domain login is not accepted.GoodThe login uses a backup-specific administrative account through the separate mechanism, and the log shows no production-directory authentication events.
link

Cross-framework mappings

How ISM-2152 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
handshakeSupports(1)expand_less
Annex A 8.22ISM-2152 requires backup infrastructure to be segregated from production and to use a separate authentication mechanism for administrativ...

E8

ControlNotesDetails
handshakeSupports(4)expand_less
E8-RB-ML1.6ISM-2152 requires segregation of backup infrastructure from production and separate administrative authentication for backup administration
E8-RB-ML2.1ISM-2152 requires segregating backup servers/repositories/consoles from production and using separate administrative authentication for b...
E8-RB-ML2.2ISM-2152 requires backup infrastructure to be segregated from production environments and administered via a separate authentication mech...
E8-RB-ML3.2ISM-2152 requires segregated backup infrastructure and separate administrative authentication from production

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system management controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls